A report by the United Kingdom’s National Health Service is warning of threats leveraging Log4Shell vulnerability in VMware Horizon servers by an unknown cyber actor. The NHS said the attacks are designed to establish persistence with affective networks, likely as part of a reconnaissance phase. In doing so, the attackers use the Java Naming and Directory Interface via Log4Shell payloads to call back to malicious infrastructure. Once weaknesses are identified, the attack uses the Lightweight Directory Access Protocol to retrieve and execute a malicious Java class file that injects a web shell into the VM Blast Secure Gateway service.

Related News Articles

Headline
The Cybersecurity and Infrastructure Security Agency and Food and Drug Administration Jan. 30 released notices warning of vulnerabilities found in the Contec…
Headline
The AHA yesterday released an advisory alerting members that the association and the Health Information Sharing and Analysis Center have identified attempted…
Headline
The ransomware attack last year against UnitedHealth Group subsidiary Change Healthcare exposed data of more than 190 million people — up from previous reports…
Headline
The Cybersecurity and Infrastructure Security Agency and FBI Jan. 22 released an advisory explaining how cyberthreat actors “chained” vulnerabilities —…
Headline
A guide published Jan. 13 by the Cybersecurity and Infrastructure Security Agency, National Security Agency, FBI, Environmental Protection Agency,…
Headline
In the last of this four-part conversation, four leaders from Scripps Health — Chris Van Gorder, president and CEO, Todd Walbridge, senior director of…